Thousands of legitimate websites have been compromised by hackers who exploit flaws in outdated plugins to turn them into malware hubs via a fake Google Chrome update page. Clicking the ‘update’ button launches malware downloads, stealing private information or acting as a conduit for further malware or ransomware. Over 10,000 WordPress sites are known to have been affected.

GhostClaw steals crypto wallet data from devs – Cryptonews.net
GhostClaw steals crypto wallet data from devs Cryptonews.net
